CVE-2026-86830
nicheIncorrect Privilege Assignment in AWS TEAM for IAM Identity Center (pre-1.5.1)
AWS Temporary Elevated Access Management (TEAM), an AWS Solutions deployment for IAM Identity Center that brokers temporary elevated access, contains an incorrect privilege assignment (CWE-266) in all versions before 1.5.1. Any authenticated remote user who already has application-level access to a TEAM instance can read, approve, modify, or revoke arbitrary access requests, effectively self-approving elevated access and gaining unintended temporary administrative permissions in the AWS accounts managed by that deployment. The flaw requires valid credentials to the application (high privileges per the CVSS 4.0 vector) but no user interaction, and yields high impact on confidentiality, integrity, and availability of the affected accounts. Organizations running TEAM versions prior to 1.5.1, including forks or derivative implementations, are affected. No public proof of concept is known and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog as of this analysis.
What to do: Upgrade TEAM to version 1.5.1 or later as soon as possible, and apply the same fixes to any forked or customized copies of the solution since they will not receive automatic updates. Review TEAM and CloudTrail audit logs for access requests that were approved, modified, or revoked by users who should not have approver rights, and validate that all temporary elevated grants during the vulnerable period were legitimate. As a compensating control, restrict application-level access to TEAM and tighten approval-group membership until the upgrade is complete.
| Amazon Web Services (AWS) Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center | before 1.5.1 (fixed in 1.5.1 and later) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
- Weakness
- CWE-266
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.